What PDPL Is and Why the Clock Has Already Started
Saudi Arabia's Personal Data Protection Law came into full effect in September 2023. A two-year grace period gave businesses time to prepare, and that window has now closed. The law is live, the regulator is active, and businesses that spent those two years telling themselves they would get to it eventually are now carrying real legal exposure.
PDPL is the Kingdom's first comprehensive data protection framework. It draws some inspiration from Europe's GDPR, but it was shaped by the specific legal, cultural, and commercial context of Saudi Arabia. That distinction matters, because businesses that assume their existing GDPR programme covers them are in for an unpleasant surprise when they look at the detail.
The most important thing to understand upfront is that this law follows the data, not the company. It applies to any organisation that collects, processes, or stores the personal data of individuals located in Saudi Arabia, regardless of where that organisation is physically based. A consultancy in Bahrain, a SaaS company in Dubai, an e-commerce retailer in the UK: if any of them handle data belonging to Saudi residents, PDPL applies to them.
The Saudi Data and Artificial Intelligence Authority, known as SDAIA, is responsible for enforcement. Since the law came into force they have been processing complaints, issuing guidance, and making it clear that this is not an aspirational document. It is an enforceable one.
Who It Applies To and Where Businesses Go Wrong
The most persistent misconception we encounter is that PDPL only concerns large businesses or companies operating in regulated industries like banking or healthcare. That is not how the law works. A ten-person professional services firm with a CRM full of Saudi client contacts is processing personal data subject to PDPL. An online retailer that ships to Saudi addresses is too. A SaaS platform with Saudi users whose activity data gets collected through the product is also caught.
Personal data under PDPL covers any information that identifies or could reasonably identify a specific individual: names, phone numbers, email addresses, national ID numbers, location data, financial details, health records. The breadth is significant, and most businesses are processing more of it than they initially realise once they actually sit down and map what they hold.
The law also has a separate, stricter category for sensitive personal data. This includes health and medical information, financial records, criminal history, biometric data, and information about religious beliefs or political opinions. Processing data in this category requires greater care, stricter justification, and carries heavier consequences if something goes wrong.
What PDPL Actually Requires You to Do
Breaking PDPL down into its core obligations makes it far less overwhelming. Six areas cover most of what a business needs to address.
A lawful basis for every processing activity. Every time your business collects or uses personal data, there needs to be a legal justification for doing so. Consent is the most common basis for commercial organisations, but it has specific requirements around how it is obtained and recorded. Other bases exist, such as contractual necessity and legitimate interests, but each comes with its own conditions.
Transparent privacy notices. Individuals have the right to know what data you are collecting, why, who you are sharing it with, how long you are keeping it, and what rights they have over it, communicated in language an ordinary person can actually read. Most privacy notices we see in practice would fail that test.
Procedures for data subject rights. People whose data you hold have the right to access it, correct inaccuracies, request deletion, and object to certain types of processing. You need workable processes for handling these requests within the statutory timeframe, thirty days in most cases.
A documented data retention policy. Keeping personal data indefinitely because you might need it someday is not compliant. PDPL requires that data be deleted or anonymised once it is no longer needed for the purpose it was collected for.
Controls on cross-border data transfers. Sending personal data outside Saudi Arabia is restricted. You need SDAIA approval, confirmation the destination country offers adequate protection, or appropriate safeguards. Most cloud services store data outside the Kingdom, which means this affects virtually every business using modern software tools.
A breach notification procedure. If a qualifying breach occurs, you have seventy-two hours to notify SDAIA. Without a procedure prepared in advance, seventy-two hours is not very long to make high-stakes decisions under pressure.
A Practical Ninety-Day Roadmap for SMEs
The businesses that reach a defensible compliance position quickly are not the ones with the largest legal teams. They are the ones that approach this in a structured sequence rather than trying to address everything at once.
Weeks one and two: data mapping. You cannot protect what you have not identified. Map every place personal data enters, moves through, and is stored within your business.
Weeks three to six: policies and lawful basis. Draft the privacy notice, establish lawful bases for each processing activity, and put data subject request procedures in place.
Weeks seven to ten: technical and vendor controls. Review access controls, retention enforcement, and the data processing agreements you have with vendors handling data on your behalf.
Weeks eleven to thirteen: breach readiness and review. Finalise the breach notification procedure, brief your team, and conduct an internal review before treating the programme as business as usual.
This is precisely the sequence our vDPO service runs for clients, adapted to the specific data your business actually processes.
